Continuing Improvements. Tell Us How We’re Driving! Send us Feedback
This Story is Archived

Hacking Into Blogs - Is Your Blog Safe? »

Posted by: Webfeed 2 years ago
8.2

Scale of 1 to 10

Read: 40

Propped: 91

Comments: 23

Archived

There is a flaw in many blogging platforms, including WordPress, that would allow others to gain access to post and gain administrative privleges. Over the weekend, Jason Schramm was able to exploit a Host Overflow Application eXception vulnerability in RSS.

Read Full Story at webfeedcentral.com »
Submitted By:
Webfeed

I'll play Devil's advocate for both sides of any story. Interests include (but are not limited to) Technology, Mass Media (new & old), Politics ...

 

This Story is Archived and Commenting is Closed

Comments: 25
  • Avg rating: (+0/-0 0)PaganGodess
    PaganGodess
    Oct. 2, 2006, 7:23 p.m.

    So, next time I get drunk, open up a can of loud mouth and really enrage everyone I'll blame it on the "hacker" who stole my identity! = ] Hmmmm . . . . hope they fix this in a hurry!

    • Avg rating: (+0/-0 0)STONERS
      STONERS
      Oct. 2, 2006, 8:07 p.m.

      Well isnt this some s**t!!!!Hope for a quick fix...Hello PaganGodess..:}:}

      • Avg rating: (+0/-0 0)not2needy
        not2needy
        Oct. 2, 2006, 9:38 p.m.

        Hmmm, Gives us something to think about when we spout something offensive in these threads that may peeeee someone off.

        • Avg rating: (+0/-0 0)rvdad
          rvdad
          Oct. 3, 2006, 7:47 a.m.

          Mark Woodman has more.

          http://inkblots.markwoodman.com/2006/10/03/websites-hacked-through-metaweblog-api/

          • Avg rating: (+0/-0 0)michaelgray
            michaelgray
            Oct. 3, 2006, 9:26 a.m.

            why not give a little help in fixing the problem instead running around putting up digital graffiti.

            • Avg rating: (+3/-0 3)rvdad
              rvdad
              Oct. 3, 2006, 9:52 a.m.

              We are currently working on Wordpress plug-in that fixes the problem. And there already is a Typepad widget in-testing called Shield that fixes the problem.

              http://www.kbcafe.com/iBLOGthere4iM/?guid=20061002114409

              • Avg rating: (+2/-0 2)rvdad
                rvdad
                Oct. 3, 2006, 10:26 a.m.

                ok, I just confirmed there's a patch for Wordpress. I'll post the link in a second. But understand, my own website has been down because of the traffic, so be patient.

                • Avg rating: (+0/-0 0)Webreader
                  Webreader
                  Oct. 3, 2006, 11 a.m.

                  This goes into the "Isn't anything safe anymore?" file. This story is full of "geektalk" which is way over my head, therefore I would LUV it if someone could translate this for one who is simply a user and sampler of opinions. I have the utmost respect for anyone who can handle the complex world of our sci-fi, now sci-fact communication system. Go geeks! but we collectively need to make 'honesty' hip again, because in the long run everyone wins, and humankind can make even more progress.

                  • Avg rating: (+0/-0 0)Webreader
                    Webreader
                    Oct. 3, 2006, 11:03 a.m.

                    Does this mean that when I read something submitted by, say, "jblogger," that it isn't necessarily jblogger who wrote it? Can someone hijack my 'handle' and post some awful invective to get me in trouble?

                    • Avg rating: (+2/-0 2)rvdad
                      rvdad
                      Oct. 3, 2006, 11:38 a.m.

                      OK, here's the Wordpress patch

                      http://www.jasonblogs.com/2006/10/03/patch-for-host-overflow-application-exception/

                      • Avg rating: (+3/-0 3)rvdad
                        rvdad
                        Oct. 3, 2006, 12:32 p.m.

                        The plug-in is 404 at the moment. I've pinged Jason.

                        • Avg rating: (+20/-0 20)jonnichols
                          jonnichols
                          Oct. 3, 2006, 1:47 p.m.

                          Waiting for the wordpress plugin to come back online....

                          • Avg rating: (+13/-2 11)rvdad
                            rvdad
                            Oct. 3, 2006, 1:56 p.m.

                            I put a non-broken link in the comments of Jason's blog entry.

                            • Avg rating: (+0/-0 0)shiwej
                              shiwej
                              Oct. 3, 2006, 2:46 p.m.

                              I fixed the download link on JasonBlogs.com. Sorry for the delay.

                              • Avg rating: (+0/-0 0)bonaroo
                                bonaroo
                                Oct. 4, 2006, 11:30 a.m.

                                Webfeed

                                Thanks for the heads up.

                                • Avg rating: (+0/-0 0)2sidestoeverything
                                  2sidestoeverything
                                  Oct. 4, 2006, 2:52 p.m.

                                  Webfeed,

                                  Good article thanks for sharing it.

                                  • Avg rating: (+1/-1 0)Eagle_Eye
                                    Eagle_Eye
                                    Oct. 5, 2006, 9:12 p.m.

                                    If they can steal you on paper then they can steal you in cyberspace!!

                                    Good information, but a bit to technical for my "need to be user friendly" mind.

                                    • Avg rating: (+0/-0 0)dtress1d
                                      dtress1d
                                      Oct. 10, 2006, 1:01 p.m.

                                      I agree, most of the applications that can and are gotten to via the internet can and are available for those who know how.

                                      There are ways of making this less easy, but most companies do not use these methods.

                                      Sometimes it is lack of knowledge, sometimes lack of expertise, sometimes lack of money, but mainly just that they don't care!

                                      • Avg rating: (+0/-0 0)topperjax
                                        topperjax
                                        Oct. 13, 2006, 1:51 a.m.

                                        I don't really think that it's that they don't care, it's more that it seems that whether we care or not, if a hacker wants into my system, he'll get there, no matter what safe guards I have up. That's the part that I hate the most.

                                        • Avg rating: (+0/-0 0)chinjungpr09
                                          chinjungpr09
                                          June 23, 2008, 2:53 a.m.

                                          i do many blogs , thanks for this post

                                          • Avg rating: (+0/-0 0)doraemonpr10
                                            doraemonpr10
                                            June 23, 2008, 2:55 a.m.

                                            rvdad ,thanks for patch

                                            • Avg rating: (+0/-0 0)nobetapr16
                                              nobetapr16
                                              June 26, 2008, 12:09 a.m.

                                              How is my wp2.51 blog safe?

                                              • Avg rating: (+0/-0 0)zuneopr17
                                                zuneopr17
                                                June 26, 2008, 12:14 a.m.

                                                Good information,thanks

                                                The first 23 comments are shown. Show all 25 comments »

                                                Advertisement